Protective DNS: a threat layer behind the office firewall
Office networks carry managed laptops, personal phones and visitors in the same building. Shield blocks command-and-control callbacks at the lookup, flags new threats early and keeps staff and guest networks on their own rules, without one more agent to push.
- Open
- Secure
- xPSK
Guest and BYOD devices, no agent
What is at stake
Managed and unmanaged devices in one building
BYOD and visitors
Devices no agent will ever reach still share the building's WiFi.Devices calling home
An infected device reaching its command-and-control server is a breach in progress.Ageing firewalls
Firmware falls behind. A DNS layer closes the gap.
How Shield fits
Staff and guests on their own rules
- Staff on EAP-TLS with MDMThreat defense first, with staff allow and block lists.
- Guest WiFiFamily-safe categories and ad blocking, so pages load up to 500% faster.
- Tenants and IoTxPSK networks on their own VLANs and policies.
- ReportingThreat analysis and blocked URLs, by network.
Need logs in your SIEM, or Shield behind an existing firewall and NAC? Talk it through with a Shield expert.
See everything Shield stopsSecure staff networks on Purple Access
Blocked at the lookup
- Command-and-control callback
- Phishing domain
- Malware domain
- Newly flagged domain
Proof
Earlier warning, lighter networks
- 10 days
- earlier warning of new threats than standard blocklists
- 62%
- fewer DNS queries with ads stripped
- ISO 27001certified, alongside GDPR, CCPA and Cyber Essentials
FAQ
Questions we hear from teams like yours
We already have a firewall. Why add Shield?
Shield is a layer behind it. It stops the lookup before a connection starts, blocks command-and-control callbacks and covers devices an endpoint agent never touches.
Can staff and guests have different rules?
Yes. Each SSID and VLAN carries its own policy.
Other industries
Hospitality
Family-safe, faster guest WiFi with protective DNS for pubs, hotels and venues
Family-safe guest WiFi and faster pages for pubs, hotels and family venues.Education and student accommodation
Safeguarding on every student and resident network
Safeguarding per network and per VLAN for schools, campuses and student accommodation.Healthcare
Around 241,000 threats a week, stopped on hospital guest WiFi
Threat defense on patient and visitor WiFi, proven at St George's Healthcare NHS Trust.
Decide what your WiFi reaches, free for 30 days
Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.
- We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
- You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
- You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.
Your policy map
Tell us your networks. We map a policy to each one.
A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.